NAKIVO Backup & Replicationí§ÒâÎļþ¶ÁÈ¡Îó²î(CVE-2024-48248)À´Ï®£¬£¬ÈËÉú¾ÍÊDz©Ìṩ½â¾ö¼Æ»®

Ðû²¼Ê±¼ä 2025-02-28

NAKIVO Backup & Replication ÊÇÒ»¿îרעÓÚÐéÄ⻯¡¢Ôƶ˼°»ìÏýÇéÐεı¸·ÝÓëÔÖÄѻָ´µÄ½â¾ö¼Æ»®£¬£¬ÊÊÓÃÓÚ VMware vSphere¡¢Microsoft Hyper-V¡¢Nutanix AHV¡¢Amazon EC2¡¢Windows/Linux ºÍ Microsoft 365 ÇéÐΡ£¡£¡£¡£±¸·ÝЧÀÍÆ÷¿ÉÒÔ×°ÖÃÔÚ Windows¡¢Linux ºÍ NAS ²Ù×÷ϵͳÉÏ£¬£¬ÓÈÆäÊʺÏÖÐСÆóÒµÊг¡¡£¡£¡£¡£


2025Äê2Ô£¬£¬ÈËÉú¾ÍÊDz©¼à¿Øµ½µ½¹Ù·½ÐÞ¸´NAKIVO Backup & Replicationí§ÒâÎļþ¶ÁÈ¡Îó²î(CVE-2024-48248)£¬£¬¹¥»÷Õß¿ÉʹÓÃSTPreLoadManagement ÀàÖÐµÄ getImageByPathÒªÁ죬£¬Èƹý·¾¶ÑéÖ¤²¢¶ÁȡĿµÄЧÀÍÆ÷ÉϵÄí§ÒâÎļþ£¨°üÀ¨Ãô¸ÐÉèÖÃÎļþ¡¢Êý¾Ý¿â¡¢±¸·ÝÈÕÖ¾µÈ£©


1.png

¡¾Îó²î¸´ÏÖ½ØÍ¼¡¿

 

 

2.png

3.png

¡¾Ó°Ïì°æ±¾¡¿


NAKIVO Backup & Replication < v11.0.0.88174


¡¾ÐÞ¸´½¨Òé¡¿


Ò»¡¢¹Ù·½ÐÞ¸´¼Æ»®£º

ÏÖÔÚ¹Ù·½ÒÑÐû²¼Çå¾²¸üУ¬£¬½¨ÒéÓû§¾¡¿ìÉý¼¶ÖÁ×îа汾£º

https://www.nakivo.com/resources/download/trial-download/download/


¶þ¡¢ÈËÉú¾ÍÊDz©¼Æ»®£º


1¡¢ÈËÉú¾ÍÊDz©¼ì²âÀà²úÆ·¼Æ»®


ÌìãÙÈëÇÖ¼ì²âÓëÖÎÀíϵͳ£¨IDS£©£¬£¬Éý¼¶µ½×îа汾

ÌìãÙ³¬Èںϼì²â̽Õ루CSP£©£¬£¬Éý¼¶µ½×îа汾

ÌìãÙÍþвÆÊÎöÒ»Ìå»ú£¨TAR£©£¬£¬Éý¼¶µ½×îа汾

ÌìÇåWEBÇå¾²Ó¦ÓÃÍø¹Ø£¨WAF£©£¬£¬Éý¼¶µ½×îа汾

ÌìÇåÈëÇÖ·ÀÓùϵͳ£¨IPS£©£¬£¬Éý¼¶µ½×îа汾


¼´¿ÉÓÐÓüì²â»ò·À»¤¸ÃÎó²îÔì³ÉµÄ¹¥»÷Σº¦£¬£¬ÊÂÎñ¿âÏÂÔØµØµã£º

ÊÂÎñ¿âÏÂÔØµØµã£ºhttps://venustech.download.venuscloud.cn/


2¡¢ÈËÉú¾ÍÊDz©Â©É¨²úÆ·¼Æ»®


£¨1£©¡°ÈËÉú¾ÍÊDz©Îó²îɨÃèϵͳV6.0¡±²úÆ·ÒÑÖ§³Ö¶Ô¸ÃÎó²î¾ÙÐÐɨÃè

 4.png


£¨2£©ÈËÉú¾ÍÊDz©Îó²îɨÃèϵͳ608XϵÁа汾ÒÑÖ§³Ö¶Ô¸ÃÎó²î¾ÙÐÐɨÃè

 5.png


3¡¢ÈËÉú¾ÍÊDz©×ʲúÓëųÈõÐÔÖÎÀíÆ½Ì¨²úÆ·¼Æ»®


ÈËÉú¾ÍÊDz©×ʲúÓëųÈõÐÔÖÎÀíÆ½Ì¨ÊµÊ±ÊÕÂÞ²¢¸üÐÂÇ鱨ÐÅÏ¢£¬£¬¶ÔÈë¿â×ʲúNAKIVO Backup & Replicationí§ÒâÎļþ¶ÁÈ¡Îó²î(CVE-2024-48248)¾ÙÐÐÖÎÀí¡£¡£¡£¡£

6.png 


4¡¢ÈËÉú¾ÍÊDz©Çå¾²ÖÎÀíºÍÌ¬ÊÆ¸Ð֪ƽ̨²úÆ·¼Æ»®


Óû§¿ÉÒÔͨ¹ýÌ©ºÏÇå¾²ÖÎÀíºÍÌ¬ÊÆ¸Ð֪ƽ̨£¬£¬¾ÙÐйØÁªÕ½ÂÔÉèÖ㬣¬Á¬ÏµÏÖÕæÏàÐÎÖÐϵͳÈÕÖ¾ºÍÇå¾²×°±¸µÄ¸æ¾¯ÐÅÏ¢¾ÙÐÐÒ»Á¬¼à¿Ø£¬£¬´Ó¶ø·¢Ã÷¡°NAKIVO Backup & Replicationí§ÒâÎļþ¶ÁÈ¡Îó²î(CVE-2024-48248)¡±µÄÎó²îʹÓù¥»÷ÐÐΪ¡£¡£¡£¡£


1£©ÔÚÌ©ºÏµÄƽ̨ÖУ¬£¬Í¨¹ýųÈõÐÔ·¢Ã÷¹¦Ð§Õë¶Ô¡°NAKIVO Backup & Replicationí§ÒâÎļþ¶ÁÈ¡Îó²î(CVE-2024-48248)¡±Îó²îɨÃèʹÃü£¬£¬ÅŲéÖÎÀíÍøÂçÖÐÊÜ´ËÎó²îÓ°ÏìµÄÖ÷Òª×ʲú£» £»£»£»£»£»

7.png 


2£©Æ½Ì¨¡°¹ØÁªÆÊÎö¡±Ä£¿£¿£¿£¿£¿£¿éÖУ¬£¬Ìí¼Ó¡°L2_NAKIVO_Backup_Replicationí§ÒâÎļþ¶ÁÈ¡Îó²î(CVE-2024-48248)¡±£¬£¬Í¨¹ýÈËÉú¾ÍÊDz©¼ì²â×°±¸¡¢Ä¿µÄÖ÷»úϵͳµÈ×°±¸µÄ¸æ¾¯ÈÕÖ¾£¬£¬·¢Ã÷Íⲿ¹¥»÷ÐÐΪ£º

8.png 


̫ͨ¹ýÎö¹æÔò×Ô¶¯½«"L2_NAKIVO_Backup_Replicationí§ÒâÎļþ¶ÁÈ¡Îó²î(CVE-2024-48248)"Îó²îʹÓõĿÉÒÉÐÐΪԴµØµãÌí¼Óµ½ÊÓ²ìÁÐ±í¡°¸ßΣº¦ÅþÁ¬¡±ÖУ¬£¬×÷ΪÄÚ²¿Ç鱨Êý¾ÝʹÓã» £»£»£»£»£»


3£©Ìí¼Ó¡°L3_NAKIVO_Backup_Replicationí§ÒâÎļþ¶ÁÈ¡Îó²î(CVE-2024-48248)¡±£¬£¬Ìõ¼þÈÕÖ¾Ãû³Æ¼´ÊÇ»ò°üÀ¨¡°L2_NAKIVO_Backup_Replicationí§ÒâÎļþ¶ÁÈ¡Îó²î(CVE-2024-48248)¡±£¬£¬¹¥»÷Ч¹û¼´ÊÇ¡°¹¥»÷Àֳɡ±£¬£¬Ä¿µÄµØµãÒýÓÃ×ʲúÎó²î»òÔ´µØµãÆ¥ÅäÍþвÇ鱨£¬£¬´Ó¶øÌáÉý¹ØÁª¹æÔòµÄÖÃÐŶÈ¡£¡£¡£¡£

9.png